Fake defense jobs deliver Troy backdoor via Windows kernel bug

Check Point ties a Windows zero-day to Lazarus attacks on defense firms using fake job offers.

CSBadmin
2 Min Read

Check Point Research has tied the Lazarus Group to zero-day exploitation of a Windows kernel flaw in a new wave of the Operation Dream Job campaign targeting defense and aerospace companies in France, Germany, Brazil, and India. The attackers abuse CVE-2026-68820 (CVSS 7.0), a privilege escalation bug in the AFD.sys Winsock driver that Microsoft patched in the August 2026 Patch Tuesday release.

Both infection chains start with recruiter bait. In the first, victims open an encrypted archive that triggers a DLL side-loading chain; the malicious libmupdf.dll shows a fake Lockheed Martin job description while loading the MISTPEN downloader in memory. MISTPEN fires the AFD.sys exploit for SYSTEM rights, then deploys the ForestTiger backdoor and a FudModule 3.1 rootkit update that can disable Windows Smart App Control. The second route pushes a trojanized SecurityPDF viewer from sites posing as privacy firm Enveil, which decrypts an embedded payload and runs the Troy backdoor straight from memory.

Command infrastructure is built from compromised WordPress and SharePoint sites and vulnerable Roundcube webmail servers, many running the RelayShell PHP webshell. Check Point found at least 17 server identifiers in the relay network, with operators connecting through commercial VPNs.

The campaign shows attackers weaving legitimate infrastructure into every stage of the operation, which makes phishing harder to spot. Security teams should apply the August Patch Tuesday update, review Check Point’s indicators of compromise, and treat unsolicited recruiting outreach with the same suspicion as any unverified download request.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.